Handle environment variable syntax in terminal command auto-approval #259205
+114
−4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The terminal command auto-approval feature was not correctly handling commands that start with environment variable assignments, such as
FOO=bar env | grep FOO
. The auto-approval logic would test the entire command string against the rules, causing commands like this to be denied even when the actual command part (env
) was in the approved list.Changes Made
_extractCommandFromEnvAssignments()
method that parses environment variable assignments at the beginning of commands and extracts the actual command part_commandMatchesRegex()
method to use the extracted command for pattern matching instead of the full command stringVAR=value
syntax (falls back to bourne shell for unknown shells)$env:VAR='value'
syntax)Before the Fix
After the Fix
Examples of Supported Syntax
FOO=bar command
→ extractscommand
FOO=bar BAZ=qux command
→ extractscommand
MESSAGE="hello world" command
→ extractscommand
GREETING='hello there' command
→ extractscommand
FOO= command
→ extractscommand
(empty value)VAR=value command
→ extractscommand
(handles whitespace)The implementation maintains full backward compatibility and adds comprehensive test coverage for various edge cases.
Fixes #259201.
Warning
Firewall rules blocked me from connecting to one or more addresses
I tried to connect to the following addresses, but was blocked by firewall rules:
electronjs.org
node-gyp
(dns block)If you need me to access, download, or install something from one of these locations, you can either:
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.